Menu
Browse

Cyber Incident Victim: TriWest Healthcare Alliance

Date:

Apr 2026

Location:

United States of America

Summary

TriWest Healthcare Alliance discovered a security incident in which an unauthorized person gained limited access to its systems and downloaded protected health information affecting 11,844 beneficiaries. The compromised data included names, Department of Defense Benefits Numbers and ZIP codes, with fewer than five cases also exposing Social Security numbers, addresses and dates of birth. The company notified affected individuals, offered a free credit‑monitoring service through Experian for 24 months, provided a breach response telephone line and indicated that those who suspect identity theft may file a report with the Federal Trade Commission. A third‑party forensic expert was engaged to review the accessed data, and the company subsequently strengthened password‑reset controls, enhanced system access monitoring and expanded employee training on cyber‑attack mitigation.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

TriWest Healthcare Alliance officials discovered a security incident on April 16 in which an unauthorized person gained limited, unauthorized access to TriWest information and downloaded it. The company stated that, as soon as the incident was discovered, it took immediate action to prevent any further unauthorized activity and worked diligently with the government to notify affected individuals consistent with applicable law and notification timelines. A letter to one beneficiary dated July 2, provided to Military Times, indicated that the breach may have affected protected health information and that 11,844 beneficiaries were notified. TriWest officials said they are unaware of any misuse of the information obtained. The unauthorized person obtained health‑related and other personal information, specifically names, Department of Defense Benefits Numbers and beneficiaries’ ZIP codes. In fewer than five instances, the information also included Social Security numbers, addresses and dates of birth. About four million beneficiaries are covered by TriWest, the managed care contractor for the Tricare West Region, which serves active duty, retired, National Guard and Reserve members, their family members, survivors and certain former spouses under the DoD’s Tricare program with eligibility determined by DEERS. TriWest is notifying each beneficiary about what information was involved in their specific case. The timing of the notifications was unclear, since at least one letter was dated July 2, about two and a half months after the incident occurred.

Cyber Incident Image

TriWest hired a third‑party forensic expert to review what information was accessed during the incident. The company offered a free credit‑monitoring service through Experian for 24 months to those who feel it is needed, advising beneficiaries to enroll by the deadline provided in their notification letter using the activation code and instructions included. Beneficiaries who detect suspicious activity were instructed to contact the TriWest Healthcare Alliance Breach Response Line at 1‑833‑918‑1296. Those who believe they are victims of identity theft were advised to file a report with the Federal Trade Commission at identitytheft.gov. TriWest said it has taken steps to prevent any other such incidents, including increasing security controls related to password resets, strengthening system access monitoring tools and providing additional employee education on identifying and mitigating the different types of cyber attacks. The notifications were intended to inform affected individuals about the specific data elements that may have been compromised and to provide resources for monitoring and responding to potential misuse. No further details about the attacker’s identity, motives or the exact systems accessed were disclosed in the available source material. The narrative concludes with the confirmed actions taken by TriWest following the discovery and disclosure of the breach.

Sources
Sources available to members
1 source